Today, all of the sudden, without doing any changes to Mikrotik, I lost internet connection. After some investigation I’ve found this fault message:
DoH server connection error: SSL: handshake failed: unable to get local issuer certificate (6)
I know that there are tons of forum entries about this topic. I just wanted to ask if there is somebody else using QUAD9 DoH servers and can confirm that problem exists. I do not know whether it is problem at Mikrotik side (I doubt as I did not make any changes nor updates) or something is really wrong with Quad9 certificates.
The only way to workaround this issues is to remove tick mark from Verify DoH Certificate. Then it works. For safety reasons I went back to ISP DNS servers until I find out what is going on.
As I said, everything was working without any issues until today, this is not new setup. It was fully working setup until it stopped all of the sudden today. And yes, I have already had Root CA certificate, but it was a bit different than in the post you mentioned. I was using this one:
I thought about that. Certificate is valid until 2031 and I have also downloaded new version in case it was renewed. Still same issue. I have also checked date and time on router and it is ok.
It is strange as it happened all of the sudden. Internet was just gone without doing anything.
If Root CA is used by Mikrotik to validate DoH certificate, could it be problem then on Mikrotik side? Anyone else using this:
The validation chain changed. DigiCert switched roots, as the CA certificate fingerprints don’t match. They’re now using “DigiCert Global Root G3”. Import DigiCertGlobalRootG3.crt.pem from https://www.digicert.com/kb/digicert-root-certificates.htm and it will fix the issue.
then issue is still there. If I download DigiCertGlobalRootG3.crt.pem direclty from https://www.digicert.com/kb/digicert-root-certificates.htm as suggested by macropin, then all works like a charm. It is a bit strange that Quad9 guys have link to wrong certificate in their description.
I’m not sure I’m doing everthing right but I can reproduce the error that nacardin was having with dns.eu or quad9 too.
The certitfcate-chains have been downloaded and imported for both. static entries have been set for IP4 and IP6 settings. The servers are pingable from the Mikrotik but the certificates are not verified properly as is seems.